SlideShare a Scribd company logo
Data Privacy Compliance. Why? How?
Julian Cunningham-Day, Linklaters
Pekka Hukkanen, Outotec
Mike Pewton, Solium GSP
Nancy Price, Linklaters
Agenda
•  Why is data privacy relevant for incentives?
•  What does data privacy law protect?
•  Who is subject to the law?
•  What does it mean in practice for your plan?
•  A company’s experience - Outotec
•  How to be compliant – globally
Why is data privacy relevant for incentives?
•  Over 100 countries now have data privacy laws
•  Wide ranging – not just for incentives
•  Publicity and penalties
•  Consider in context of employment relationship
•  Involvement of third parties
•  Global: more countries = more complexity
•  Practical compliance - can’t you just get
consent?
Why do we have data protection laws?
1950:	
  European	
  Conven-on	
  on	
  
Human	
  Rights	
  	
  
(Ar-cle	
  8,	
  Right	
  to	
  Privacy)	
  
1981:	
  Conven-on	
  for	
  the	
  
Protec-on	
  of	
  Individuals	
  with	
  
regard	
  to	
  Automa-c	
  Processing	
  
of	
  Personal	
  Data	
  
1995:	
  EU	
  Direc-ve	
  on	
  the	
  protec-on	
  
of	
  individuals	
  with	
  regard	
  to	
  the	
  
processing	
  of	
  personal	
  data	
  and	
  on	
  
the	
  free	
  movement	
  of	
  such	
  data	
  
2002:	
  EU	
  Direc-ve	
  on	
  the	
  
processing	
  of	
  personal	
  data	
  and	
  
the	
  protec-on	
  of	
  privacy	
  in	
  the	
  
electronic	
  communica-ons	
  sector	
  
2012:	
  Proposed	
  new	
  Regula-on	
  
to	
  reform	
  the	
  EU	
  data	
  protec-on	
  
regime	
  	
  
What does the law protect?
“Personal data processed by a data controller”
• Data relating to a living individual who can be identified
from the data
• Examples:
Ø  register of share plan participants
Ø  details of ex-employees and consultants
Ø  contact details of employees, bank account details
• Separate category of sensitive personal data
Ø  Health, racial/ethnic origin, religion
Who is subject to the law?
Ø data controller determines “how” and “why”
personal data is processed
Ø data processor processes personal data on
behalf of a data controller under a written
contract
Grantor	
   Administrator	
   Broker	
   Regulator	
  
Principle based regulation ....
1.  Fair and lawful processing
2.  Processing for specified purposes only
3.  Adequate, relevant and not excessive
4.  Accurate and up to date
5.  Kept no longer than necessary
6.  Rights of the data subject
7.  Appropriate security
8.  International transfers of personal data
Key Principles
The following are key for incentive plans:
Ø Fair and lawful processing
Ø Rights of individuals
Ø Data security/Data processors
Ø Trans-border dataflow
Ø Regulatory notifications
Key principles
Transparency	
  
•  What	
  data	
  
•  Who	
  has	
  access?	
  
•  Where?	
  
•  Why?	
  
	
  
Fair	
  and	
  lawful	
  
•  Propor-onate?	
  
•  Consent?	
  
•  Legi-mate	
  
interests?	
  	
  
Staff	
  rights	
  
•  Access	
  
•  Objec-on	
  
•  To	
  be	
  forgoSen	
  
Spotlight on data exports
Issue: International Transfers of data. Additional restrictions
apply when data is exported
Routes for
International
Data Transfers
Consent Contractual
Necessity
The Model
Contracts
A Custom
Contract
An Approved
Destination
U.S. Safe
Harbor
Binding
Corporate
Rules
Presumption
of Adequacy
How is the law enforced?
Naming	
  
and	
  
shaming	
  
Public	
  
opinion	
  
Audit/	
  
Fines	
  
Cease	
  
and	
  
Desist	
  
Private	
  
Claims	
  
International harmonisation?
EU - Minimum harmonisation
• Directive based, so many similarities between Member States…
Ø  …but national variations exist in different implementation,
interpretation and enforcement
• Proposals to reform European data protection laws shortly
Ø  Introduction of a single EU-wide data protection law via a Regulation
Ø  Stringent obligations including mandatory appointment of data
protection officers
Ø  Increased emphasis on accountability and “privacy by design”
Ø  Extra-territorial effect
Ø  Mandatory breach notification
Ø  Fines of up to 5% of annual worldwide turnover
International harmonisation?
•  Rest of the world
Ø  Now over 100 jurisdictions with developed privacy
regimes
Ø  Many based on European model
Ø  Australia – new set of 13 Australian Privacy Principles
Ø  Singapore – new Personal Data Protection Act
Ø  Russia – expected new data localisation law (requires
the personal data of Russian citizens to be stored in
databases in Russia)
Practical issues for incentive plans
•  How do these issues affect a company operating
a global plan at various stages
Ø Pre-invitation
Ø Initial invitation
Ø Making awards
Ø On vesting of awards
Ø Selling shares
Pre-invitation
•  Ensure 3rd party agreements in place
•  Review legal compliance
•  Obtain data permits
•  Make data protections filings/notifications
Initial invitation
•  Obtain consent for mailing
Ø Third party mailing
Ø Direct mailing
•  Ensure 3rd party agreements respected
•  Review data requests
•  Review consent procedure and ensure
early consent
Making awards
•  Follow established procedure
•  Record the required information only
•  Ensure testing and adequacy of record
keepers
Ø Internally
Ø Externally
Vesting/exercise of awards
•  Review vesting exercise data flow
•  Clean records
Re-invitation
•  Can you rely on previous Data Protections
Ø Follow same procedure
Ø Do not “flip” information
Ø Review drop outs and amend data accordingly
•  Outotec provides leading technologies and services for
the sustainable use of Earth’s natural resources
•  As the global leader in minerals and metals processing
technology, we have developed many breakthrough
technologies over the decades for our customers in
metals and mining industry
•  We also provide innovative solutions for industrial
water treatment, the utilization of alternative energy
sources and the chemical industry
•  Outotec shares are listed on NASDAQ OMX Helsinki
Outotec in brief
The	
  3rd
	
  
most	
  sustainable	
  company	
  
Experts	
  of	
  over	
  	
  
60	
  	
  
na@onali@es	
  
R&D,	
  
sales	
  and	
  
service	
  
centers	
  in	
  
27	
  
countries	
  	
  
Deliveries	
  to	
  
more	
  than	
  	
  
80	
  	
  
countries	
  
Net	
  sales	
  
1.4bn	
  
EUR	
  in	
  2014	
  
Objectives for ESSP
•  Share the success that employees build together
•  Support Outotec values & create One Outotec culture
•  Achieve a participation rate > 20%
Russia	
  70	
  
Australia	
  400	
  
	
  
Brazil	
  450	
  
	
  
Canada	
  230	
  
Chile	
  390	
  
	
  
Germany	
  550	
  
Netherlands	
  10	
  
Finland	
  1,500	
  
Sweden	
  250	
  
Norway	
  10	
  
South-­‐Africa	
  200	
  
India	
  100	
  
UK	
  5	
  
USA	
  150	
  
Mexico	
  35	
  
Zambia	
  	
  
20	
  
Peru	
  80	
  
	
  
Ghana	
  5	
  
UAE	
  	
  
2	
  
China	
  130	
  
Kazakhstan	
  20	
  
Indonesia	
  2	
  
	
  
The Plan: O’Share
•  Offer: buy 2 shares, get 1 free
•  1st year promotion: buy 1, get
1 free
•  Target group: All employees –
Participation voluntary
•  Earning potential: same for
everyone
•  Link to top management LTI:
LTI conditional on O’Share
participation
Extensive	
  marke-ng	
  campaign	
  &	
  branding	
  
Face-­‐to-­‐face	
  employee	
  events	
  
Transla-ons	
  into	
  6	
  languages	
  
Web-­‐based	
  communica-on	
  
Challenges
Over 20 different countries & cultures
Data	
  Privacy	
  issues	
  
Issues
•  First saving period 2013:
–  Easy to administer vs. legally bulletproof?
–  Risk of reducing take up if too complex?
•  Next saving periods 2014 onwards:
–  Who to handle existing and new participants?
Process
•  We chose active data consent option:
–  Consent from all employees allowing Outotec
to transfer data to administrator
•  Invitation to sign-up was sent only to
those who gave consent
–  2014 onwards consent ask again from
everybody excluding participants
•  Further acceptance on portal for data
consent
•  Over 1,500 participants in almost 20 countries around the world
•  Take-up >33%
China	
  18%	
  	
  
Australia	
  30	
  %	
  
	
  
Brazil	
  12	
  %	
  
	
  
Canada	
  22%	
  
Chile	
  9%	
  
	
  
Germany	
  25	
  %	
  
Netherlands	
  55%	
  
Finland	
  52%	
  
Sweden	
  55	
  	
  %	
  
Norway	
  63%	
  
South-­‐Africa	
  30	
  %	
  
India	
  30	
  %	
  
UK	
  80%	
  
USA	
  23	
  %	
  
Mexico	
  79	
  %	
  
Global take-up 34%
•  Over	
  1,500	
  par-cipants	
  in	
  nearly	
  20	
  countries	
  
•  2014	
  take-­‐up	
  33%	
  and	
  2015	
  27%	
  -­‐	
  in	
  challenging	
  business	
  situa-on	
  
Peru	
  25%	
  
	
  
Zambia	
  33%	
  
UAE	
  	
  
100%	
  
Tips for global compliance
ü  Country due diligence review
ü  Undertake regulatory notifications and check they remain
accurate and valid
ü  Give employees information on processing activities
ü  Obtain employees’ consent
ü  Have a compliant contract with the administrator
ü  Ensure all data transfers are compliant
ü  Check data is accurate and deleted if no longer needed
ü  Only process sensitive personal data for justified purposes
Thank You
Julian Cunningham-Day
Linklaters
julian.cunningham-
day@linklaters.com
Mike Pewton
Solium GSP
mike.pewton@solium.com
Pekka Hukkanen
Outotec
pekka.hukkanen@outotec.com
Nancy Price
Linklaters
nancy.price@linklaters.com

More Related Content

What's hot

Digital data
Digital dataDigital data
Digital data
ShivanandaVSeeri
 
Information Systems Audit - Ron Weber chapter 1
Information Systems Audit - Ron Weber chapter 1Information Systems Audit - Ron Weber chapter 1
Information Systems Audit - Ron Weber chapter 1
Sreekanth Narendran
 
Six major types of information systems
Six major types of information systemsSix major types of information systems
Six major types of information systems
Mohanraj V
 
Data Classification Presentation
Data Classification PresentationData Classification Presentation
Data Classification PresentationDerroylo
 
Development process of mis
Development process of misDevelopment process of mis
Development process of misHiren Selani
 
Enterprise management systems
Enterprise management systems Enterprise management systems
Enterprise management systems
Sanu Francis
 
Executive Information System
Executive Information SystemExecutive Information System
Executive Information System
university of education,Lahore
 
IT General Controls
IT General ControlsIT General Controls
IT General Controls
Cicero Ray Rufino
 
System Development Life Cycle & Implementation of MIS
System Development Life Cycle & Implementation of MISSystem Development Life Cycle & Implementation of MIS
System Development Life Cycle & Implementation of MISGeorge V James
 
Management Information System
Management Information System Management Information System
Management Information System
Ajilal
 
Transaction processing system
Transaction processing systemTransaction processing system
Transaction processing system
anjana1994
 
Information System & Business applications
Information System & Business applicationsInformation System & Business applications
Information System & Business applications
Shubham Upadhyay
 
System Development Life Cycle (SDLC)
System Development Life Cycle (SDLC)System Development Life Cycle (SDLC)
System Development Life Cycle (SDLC)
Showkot Usman
 
Management information system
Management information systemManagement information system
Management information system
Trinity Dwarka
 
Management Information Systems
Management Information SystemsManagement Information Systems
Management Information SystemsRam Dutt Shukla
 
ITGCs.pdf
ITGCs.pdfITGCs.pdf
ITGCs.pdf
ssuser918e9d1
 
Information security management
Information security managementInformation security management
Information security managementUMaine
 
MANAGEMENT INFORMATION SYSTEM- UNIT-2
MANAGEMENT INFORMATION SYSTEM- UNIT-2MANAGEMENT INFORMATION SYSTEM- UNIT-2
MANAGEMENT INFORMATION SYSTEM- UNIT-2
Manoj Kumar
 
TRANSACTION PROCESSING SYSTEM
TRANSACTION PROCESSING SYSTEMTRANSACTION PROCESSING SYSTEM
TRANSACTION PROCESSING SYSTEM
Ubaid ur Rehman
 

What's hot (20)

Digital data
Digital dataDigital data
Digital data
 
Information Systems Audit - Ron Weber chapter 1
Information Systems Audit - Ron Weber chapter 1Information Systems Audit - Ron Weber chapter 1
Information Systems Audit - Ron Weber chapter 1
 
Six major types of information systems
Six major types of information systemsSix major types of information systems
Six major types of information systems
 
Data Classification Presentation
Data Classification PresentationData Classification Presentation
Data Classification Presentation
 
Development process of mis
Development process of misDevelopment process of mis
Development process of mis
 
Enterprise management systems
Enterprise management systems Enterprise management systems
Enterprise management systems
 
Executive Information System
Executive Information SystemExecutive Information System
Executive Information System
 
ch10.ppt
ch10.pptch10.ppt
ch10.ppt
 
IT General Controls
IT General ControlsIT General Controls
IT General Controls
 
System Development Life Cycle & Implementation of MIS
System Development Life Cycle & Implementation of MISSystem Development Life Cycle & Implementation of MIS
System Development Life Cycle & Implementation of MIS
 
Management Information System
Management Information System Management Information System
Management Information System
 
Transaction processing system
Transaction processing systemTransaction processing system
Transaction processing system
 
Information System & Business applications
Information System & Business applicationsInformation System & Business applications
Information System & Business applications
 
System Development Life Cycle (SDLC)
System Development Life Cycle (SDLC)System Development Life Cycle (SDLC)
System Development Life Cycle (SDLC)
 
Management information system
Management information systemManagement information system
Management information system
 
Management Information Systems
Management Information SystemsManagement Information Systems
Management Information Systems
 
ITGCs.pdf
ITGCs.pdfITGCs.pdf
ITGCs.pdf
 
Information security management
Information security managementInformation security management
Information security management
 
MANAGEMENT INFORMATION SYSTEM- UNIT-2
MANAGEMENT INFORMATION SYSTEM- UNIT-2MANAGEMENT INFORMATION SYSTEM- UNIT-2
MANAGEMENT INFORMATION SYSTEM- UNIT-2
 
TRANSACTION PROCESSING SYSTEM
TRANSACTION PROCESSING SYSTEMTRANSACTION PROCESSING SYSTEM
TRANSACTION PROCESSING SYSTEM
 

Viewers also liked

Global Compliance: Under the Microscope
Global Compliance: Under the MicroscopeGlobal Compliance: Under the Microscope
Global Compliance: Under the Microscope
Matthew Bardsley
 
Live Long and Prosper: CEP Leadership Skills Learned from Nerd Fiction
Live Long and Prosper: CEP Leadership Skills Learned from Nerd FictionLive Long and Prosper: CEP Leadership Skills Learned from Nerd Fiction
Live Long and Prosper: CEP Leadership Skills Learned from Nerd Fiction
Andrea Huck-Esposito
 
Show Me the Money and Show Me the Shares
Show Me the Money and Show Me the SharesShow Me the Money and Show Me the Shares
Show Me the Money and Show Me the Shares
Andrea Huck-Esposito
 
GEO NECF 2015 - Currencies and Global Money Movement
GEO NECF 2015 - Currencies and Global Money Movement GEO NECF 2015 - Currencies and Global Money Movement
GEO NECF 2015 - Currencies and Global Money Movement
Andrea Huck-Esposito
 
Courses, Development Tools, and Academic Opportunities from Intel
Courses, Development Tools, and Academic Opportunities from IntelCourses, Development Tools, and Academic Opportunities from Intel
Courses, Development Tools, and Academic Opportunities from IntelIntel IT Center
 
Simplifying Settlements for Global Participants
Simplifying Settlements for Global ParticipantsSimplifying Settlements for Global Participants
Simplifying Settlements for Global Participants
Andrea Huck-Esposito
 
Data is the new oil, privacy is the new green - Eye4Travel Amsterdam
Data is the new oil, privacy is the new green - Eye4Travel AmsterdamData is the new oil, privacy is the new green - Eye4Travel Amsterdam
Data is the new oil, privacy is the new green - Eye4Travel Amsterdam
Aurélie Pols
 
Data Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethicsData Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethics
AT Internet
 
Promoting Academic Offerings - Using MarComm to Tell Your Reddie Story
Promoting Academic Offerings - Using MarComm to Tell Your Reddie StoryPromoting Academic Offerings - Using MarComm to Tell Your Reddie Story
Promoting Academic Offerings - Using MarComm to Tell Your Reddie Story
Tonya Oaks Smith
 

Viewers also liked (10)

Global Compliance: Under the Microscope
Global Compliance: Under the MicroscopeGlobal Compliance: Under the Microscope
Global Compliance: Under the Microscope
 
Live Long and Prosper: CEP Leadership Skills Learned from Nerd Fiction
Live Long and Prosper: CEP Leadership Skills Learned from Nerd FictionLive Long and Prosper: CEP Leadership Skills Learned from Nerd Fiction
Live Long and Prosper: CEP Leadership Skills Learned from Nerd Fiction
 
Show Me the Money and Show Me the Shares
Show Me the Money and Show Me the SharesShow Me the Money and Show Me the Shares
Show Me the Money and Show Me the Shares
 
GEO NECF 2015 - Currencies and Global Money Movement
GEO NECF 2015 - Currencies and Global Money Movement GEO NECF 2015 - Currencies and Global Money Movement
GEO NECF 2015 - Currencies and Global Money Movement
 
Courses, Development Tools, and Academic Opportunities from Intel
Courses, Development Tools, and Academic Opportunities from IntelCourses, Development Tools, and Academic Opportunities from Intel
Courses, Development Tools, and Academic Opportunities from Intel
 
Technology in The Classroom
Technology in The ClassroomTechnology in The Classroom
Technology in The Classroom
 
Simplifying Settlements for Global Participants
Simplifying Settlements for Global ParticipantsSimplifying Settlements for Global Participants
Simplifying Settlements for Global Participants
 
Data is the new oil, privacy is the new green - Eye4Travel Amsterdam
Data is the new oil, privacy is the new green - Eye4Travel AmsterdamData is the new oil, privacy is the new green - Eye4Travel Amsterdam
Data is the new oil, privacy is the new green - Eye4Travel Amsterdam
 
Data Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethicsData Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethics
 
Promoting Academic Offerings - Using MarComm to Tell Your Reddie Story
Promoting Academic Offerings - Using MarComm to Tell Your Reddie StoryPromoting Academic Offerings - Using MarComm to Tell Your Reddie Story
Promoting Academic Offerings - Using MarComm to Tell Your Reddie Story
 

Similar to Data Privacy Compliance: Why & How

GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
NiclasGranqvist
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...
m-hance
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
MRS
 
An introduction to data protection - Manchester - 24/06/15
An introduction to data protection - Manchester - 24/06/15An introduction to data protection - Manchester - 24/06/15
An introduction to data protection - Manchester - 24/06/15
Rachel Aldighieri
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015
Rachel Aldighieri
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014Rachel Aldighieri
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
Financial Poise
 
Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15
Rachel Aldighieri
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
ImogenRutherford
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
James Mulhern
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
PECB
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
Kwanzoo Inc
 
An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015
Rachel Aldighieri
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
Ulf Mattsson
 
Safe Harbor: A framework for US – EU data privacy
Safe Harbor: A framework for US – EU data privacy Safe Harbor: A framework for US – EU data privacy
Safe Harbor: A framework for US – EU data privacy
Raymond Cunningham
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014 Rachel Aldighieri
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protection
Rachel Aldighieri
 
Anne Cameron - An Introduction to the Data Protection Act for Researchers
Anne Cameron - An Introduction to the Data Protection Act for ResearchersAnne Cameron - An Introduction to the Data Protection Act for Researchers
Anne Cameron - An Introduction to the Data Protection Act for Researcherskclcompbio
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
Zoodikers
 

Similar to Data Privacy Compliance: Why & How (20)

GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
 
An introduction to data protection - Manchester - 24/06/15
An introduction to data protection - Manchester - 24/06/15An introduction to data protection - Manchester - 24/06/15
An introduction to data protection - Manchester - 24/06/15
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15Introduction to data protection - Edinburgh - 29/04/15
Introduction to data protection - Edinburgh - 29/04/15
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015An Introduction to Data Protection (London) - June 2015
An Introduction to Data Protection (London) - June 2015
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
Safe Harbor: A framework for US – EU data privacy
Safe Harbor: A framework for US – EU data privacy Safe Harbor: A framework for US – EU data privacy
Safe Harbor: A framework for US – EU data privacy
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protection
 
DMA Scotland: Legal update
DMA Scotland: Legal updateDMA Scotland: Legal update
DMA Scotland: Legal update
 
Anne Cameron - An Introduction to the Data Protection Act for Researchers
Anne Cameron - An Introduction to the Data Protection Act for ResearchersAnne Cameron - An Introduction to the Data Protection Act for Researchers
Anne Cameron - An Introduction to the Data Protection Act for Researchers
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 

More from Andrea Huck-Esposito

Global Tax-Advantaged Equity Compensation Plans
Global Tax-Advantaged Equity Compensation PlansGlobal Tax-Advantaged Equity Compensation Plans
Global Tax-Advantaged Equity Compensation Plans
Andrea Huck-Esposito
 
Jewel in the Crown: Signet Jewelers' Gem of an ESPP Communications Plan
Jewel in the Crown: Signet Jewelers' Gem of an ESPP Communications PlanJewel in the Crown: Signet Jewelers' Gem of an ESPP Communications Plan
Jewel in the Crown: Signet Jewelers' Gem of an ESPP Communications Plan
Andrea Huck-Esposito
 
GEO NECF 2015 - Exploring the Challenges of Tax Compliance and the W-8BEN
GEO NECF 2015 - Exploring the Challenges of Tax Compliance and the W-8BENGEO NECF 2015 - Exploring the Challenges of Tax Compliance and the W-8BEN
GEO NECF 2015 - Exploring the Challenges of Tax Compliance and the W-8BEN
Andrea Huck-Esposito
 
GEO NECF 2015 - Best Practices and Trends in Financial Reporting
GEO NECF 2015 - Best Practices and Trends in Financial ReportingGEO NECF 2015 - Best Practices and Trends in Financial Reporting
GEO NECF 2015 - Best Practices and Trends in Financial Reporting
Andrea Huck-Esposito
 
How to Impress Your CFO: A Financial Institution Case Study
How to Impress Your CFO: A Financial Institution Case StudyHow to Impress Your CFO: A Financial Institution Case Study
How to Impress Your CFO: A Financial Institution Case Study
Andrea Huck-Esposito
 
The Impact of FATCA and CRS on Employee Share Plans and Share Ownership
The Impact of FATCA and CRS on Employee Share Plans and Share OwnershipThe Impact of FATCA and CRS on Employee Share Plans and Share Ownership
The Impact of FATCA and CRS on Employee Share Plans and Share Ownership
Andrea Huck-Esposito
 
Expanding Your Global ESPP
Expanding Your Global ESPP  Expanding Your Global ESPP
Expanding Your Global ESPP
Andrea Huck-Esposito
 
The IPO & Stock Compensation
The IPO & Stock CompensationThe IPO & Stock Compensation
The IPO & Stock Compensation
Andrea Huck-Esposito
 
The power of one benefits and drawbacks of centralised share plan data slide...
The power of one benefits and drawbacks of centralised share plan data  slide...The power of one benefits and drawbacks of centralised share plan data  slide...
The power of one benefits and drawbacks of centralised share plan data slide...
Andrea Huck-Esposito
 

More from Andrea Huck-Esposito (9)

Global Tax-Advantaged Equity Compensation Plans
Global Tax-Advantaged Equity Compensation PlansGlobal Tax-Advantaged Equity Compensation Plans
Global Tax-Advantaged Equity Compensation Plans
 
Jewel in the Crown: Signet Jewelers' Gem of an ESPP Communications Plan
Jewel in the Crown: Signet Jewelers' Gem of an ESPP Communications PlanJewel in the Crown: Signet Jewelers' Gem of an ESPP Communications Plan
Jewel in the Crown: Signet Jewelers' Gem of an ESPP Communications Plan
 
GEO NECF 2015 - Exploring the Challenges of Tax Compliance and the W-8BEN
GEO NECF 2015 - Exploring the Challenges of Tax Compliance and the W-8BENGEO NECF 2015 - Exploring the Challenges of Tax Compliance and the W-8BEN
GEO NECF 2015 - Exploring the Challenges of Tax Compliance and the W-8BEN
 
GEO NECF 2015 - Best Practices and Trends in Financial Reporting
GEO NECF 2015 - Best Practices and Trends in Financial ReportingGEO NECF 2015 - Best Practices and Trends in Financial Reporting
GEO NECF 2015 - Best Practices and Trends in Financial Reporting
 
How to Impress Your CFO: A Financial Institution Case Study
How to Impress Your CFO: A Financial Institution Case StudyHow to Impress Your CFO: A Financial Institution Case Study
How to Impress Your CFO: A Financial Institution Case Study
 
The Impact of FATCA and CRS on Employee Share Plans and Share Ownership
The Impact of FATCA and CRS on Employee Share Plans and Share OwnershipThe Impact of FATCA and CRS on Employee Share Plans and Share Ownership
The Impact of FATCA and CRS on Employee Share Plans and Share Ownership
 
Expanding Your Global ESPP
Expanding Your Global ESPP  Expanding Your Global ESPP
Expanding Your Global ESPP
 
The IPO & Stock Compensation
The IPO & Stock CompensationThe IPO & Stock Compensation
The IPO & Stock Compensation
 
The power of one benefits and drawbacks of centralised share plan data slide...
The power of one benefits and drawbacks of centralised share plan data  slide...The power of one benefits and drawbacks of centralised share plan data  slide...
The power of one benefits and drawbacks of centralised share plan data slide...
 

Recently uploaded

Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptxHighlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
anjalidixit21
 
Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)
Wendy Couture
 
ASHWINI KUMAR UPADHYAY v/s Union of India.pptx
ASHWINI KUMAR UPADHYAY v/s Union of India.pptxASHWINI KUMAR UPADHYAY v/s Union of India.pptx
ASHWINI KUMAR UPADHYAY v/s Union of India.pptx
shweeta209
 
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptxRIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
OmGod1
 
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
9ib5wiwt
 
Debt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debtDebt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debt
ssuser0576e4
 
Agrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quizAgrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quiz
gaelcabigunda
 
Notes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.docNotes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.doc
BRELGOSIMAT
 
Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....
Knowyourright
 
Responsibilities of the office bearers while registering multi-state cooperat...
Responsibilities of the office bearers while registering multi-state cooperat...Responsibilities of the office bearers while registering multi-state cooperat...
Responsibilities of the office bearers while registering multi-state cooperat...
Finlaw Consultancy Pvt Ltd
 
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
9ib5wiwt
 
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdfDonald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
ssuser5750e1
 
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
Dr. Oliver Massmann
 
How to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the NetherlandsHow to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the Netherlands
BridgeWest.eu
 
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW  AN OVERVIEW in Malawi.pptxEMPLOYMENT LAW  AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
MwaiMapemba
 
DNA Testing in Civil and Criminal Matters.pptx
DNA Testing in Civil and Criminal Matters.pptxDNA Testing in Civil and Criminal Matters.pptx
DNA Testing in Civil and Criminal Matters.pptx
patrons legal
 
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
9ib5wiwt
 
Introducing New Government Regulation on Toll Road.pdf
Introducing New Government Regulation on Toll Road.pdfIntroducing New Government Regulation on Toll Road.pdf
Introducing New Government Regulation on Toll Road.pdf
AHRP Law Firm
 
The Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot CitizenshipThe Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot Citizenship
BridgeWest.eu
 
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense CounselMilitary Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Thomas (Tom) Jasper
 

Recently uploaded (20)

Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptxHighlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
 
Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)
 
ASHWINI KUMAR UPADHYAY v/s Union of India.pptx
ASHWINI KUMAR UPADHYAY v/s Union of India.pptxASHWINI KUMAR UPADHYAY v/s Union of India.pptx
ASHWINI KUMAR UPADHYAY v/s Union of India.pptx
 
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptxRIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
RIGHTS OF VICTIM EDITED PRESENTATION(SAIF JAVED).pptx
 
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
 
Debt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debtDebt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debt
 
Agrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quizAgrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quiz
 
Notes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.docNotes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.doc
 
Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....
 
Responsibilities of the office bearers while registering multi-state cooperat...
Responsibilities of the office bearers while registering multi-state cooperat...Responsibilities of the office bearers while registering multi-state cooperat...
Responsibilities of the office bearers while registering multi-state cooperat...
 
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
 
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdfDonald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
 
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
 
How to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the NetherlandsHow to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the Netherlands
 
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW  AN OVERVIEW in Malawi.pptxEMPLOYMENT LAW  AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
 
DNA Testing in Civil and Criminal Matters.pptx
DNA Testing in Civil and Criminal Matters.pptxDNA Testing in Civil and Criminal Matters.pptx
DNA Testing in Civil and Criminal Matters.pptx
 
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
 
Introducing New Government Regulation on Toll Road.pdf
Introducing New Government Regulation on Toll Road.pdfIntroducing New Government Regulation on Toll Road.pdf
Introducing New Government Regulation on Toll Road.pdf
 
The Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot CitizenshipThe Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot Citizenship
 
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense CounselMilitary Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
 

Data Privacy Compliance: Why & How

  • 1. Data Privacy Compliance. Why? How? Julian Cunningham-Day, Linklaters Pekka Hukkanen, Outotec Mike Pewton, Solium GSP Nancy Price, Linklaters
  • 2. Agenda •  Why is data privacy relevant for incentives? •  What does data privacy law protect? •  Who is subject to the law? •  What does it mean in practice for your plan? •  A company’s experience - Outotec •  How to be compliant – globally
  • 3. Why is data privacy relevant for incentives? •  Over 100 countries now have data privacy laws •  Wide ranging – not just for incentives •  Publicity and penalties •  Consider in context of employment relationship •  Involvement of third parties •  Global: more countries = more complexity •  Practical compliance - can’t you just get consent?
  • 4. Why do we have data protection laws? 1950:  European  Conven-on  on   Human  Rights     (Ar-cle  8,  Right  to  Privacy)   1981:  Conven-on  for  the   Protec-on  of  Individuals  with   regard  to  Automa-c  Processing   of  Personal  Data   1995:  EU  Direc-ve  on  the  protec-on   of  individuals  with  regard  to  the   processing  of  personal  data  and  on   the  free  movement  of  such  data   2002:  EU  Direc-ve  on  the   processing  of  personal  data  and   the  protec-on  of  privacy  in  the   electronic  communica-ons  sector   2012:  Proposed  new  Regula-on   to  reform  the  EU  data  protec-on   regime    
  • 5. What does the law protect? “Personal data processed by a data controller” • Data relating to a living individual who can be identified from the data • Examples: Ø  register of share plan participants Ø  details of ex-employees and consultants Ø  contact details of employees, bank account details • Separate category of sensitive personal data Ø  Health, racial/ethnic origin, religion
  • 6. Who is subject to the law? Ø data controller determines “how” and “why” personal data is processed Ø data processor processes personal data on behalf of a data controller under a written contract Grantor   Administrator   Broker   Regulator  
  • 7. Principle based regulation .... 1.  Fair and lawful processing 2.  Processing for specified purposes only 3.  Adequate, relevant and not excessive 4.  Accurate and up to date 5.  Kept no longer than necessary 6.  Rights of the data subject 7.  Appropriate security 8.  International transfers of personal data
  • 8. Key Principles The following are key for incentive plans: Ø Fair and lawful processing Ø Rights of individuals Ø Data security/Data processors Ø Trans-border dataflow Ø Regulatory notifications
  • 9. Key principles Transparency   •  What  data   •  Who  has  access?   •  Where?   •  Why?     Fair  and  lawful   •  Propor-onate?   •  Consent?   •  Legi-mate   interests?     Staff  rights   •  Access   •  Objec-on   •  To  be  forgoSen  
  • 10. Spotlight on data exports Issue: International Transfers of data. Additional restrictions apply when data is exported Routes for International Data Transfers Consent Contractual Necessity The Model Contracts A Custom Contract An Approved Destination U.S. Safe Harbor Binding Corporate Rules Presumption of Adequacy
  • 11. How is the law enforced? Naming   and   shaming   Public   opinion   Audit/   Fines   Cease   and   Desist   Private   Claims  
  • 12. International harmonisation? EU - Minimum harmonisation • Directive based, so many similarities between Member States… Ø  …but national variations exist in different implementation, interpretation and enforcement • Proposals to reform European data protection laws shortly Ø  Introduction of a single EU-wide data protection law via a Regulation Ø  Stringent obligations including mandatory appointment of data protection officers Ø  Increased emphasis on accountability and “privacy by design” Ø  Extra-territorial effect Ø  Mandatory breach notification Ø  Fines of up to 5% of annual worldwide turnover
  • 13. International harmonisation? •  Rest of the world Ø  Now over 100 jurisdictions with developed privacy regimes Ø  Many based on European model Ø  Australia – new set of 13 Australian Privacy Principles Ø  Singapore – new Personal Data Protection Act Ø  Russia – expected new data localisation law (requires the personal data of Russian citizens to be stored in databases in Russia)
  • 14. Practical issues for incentive plans •  How do these issues affect a company operating a global plan at various stages Ø Pre-invitation Ø Initial invitation Ø Making awards Ø On vesting of awards Ø Selling shares
  • 15. Pre-invitation •  Ensure 3rd party agreements in place •  Review legal compliance •  Obtain data permits •  Make data protections filings/notifications
  • 16. Initial invitation •  Obtain consent for mailing Ø Third party mailing Ø Direct mailing •  Ensure 3rd party agreements respected •  Review data requests •  Review consent procedure and ensure early consent
  • 17. Making awards •  Follow established procedure •  Record the required information only •  Ensure testing and adequacy of record keepers Ø Internally Ø Externally
  • 18. Vesting/exercise of awards •  Review vesting exercise data flow •  Clean records
  • 19. Re-invitation •  Can you rely on previous Data Protections Ø Follow same procedure Ø Do not “flip” information Ø Review drop outs and amend data accordingly
  • 20. •  Outotec provides leading technologies and services for the sustainable use of Earth’s natural resources •  As the global leader in minerals and metals processing technology, we have developed many breakthrough technologies over the decades for our customers in metals and mining industry •  We also provide innovative solutions for industrial water treatment, the utilization of alternative energy sources and the chemical industry •  Outotec shares are listed on NASDAQ OMX Helsinki Outotec in brief The  3rd   most  sustainable  company   Experts  of  over     60     na@onali@es   R&D,   sales  and   service   centers  in   27   countries     Deliveries  to   more  than     80     countries   Net  sales   1.4bn   EUR  in  2014  
  • 21. Objectives for ESSP •  Share the success that employees build together •  Support Outotec values & create One Outotec culture •  Achieve a participation rate > 20% Russia  70   Australia  400     Brazil  450     Canada  230   Chile  390     Germany  550   Netherlands  10   Finland  1,500   Sweden  250   Norway  10   South-­‐Africa  200   India  100   UK  5   USA  150   Mexico  35   Zambia     20   Peru  80     Ghana  5   UAE     2   China  130   Kazakhstan  20   Indonesia  2    
  • 22. The Plan: O’Share •  Offer: buy 2 shares, get 1 free •  1st year promotion: buy 1, get 1 free •  Target group: All employees – Participation voluntary •  Earning potential: same for everyone •  Link to top management LTI: LTI conditional on O’Share participation
  • 23. Extensive  marke-ng  campaign  &  branding   Face-­‐to-­‐face  employee  events   Transla-ons  into  6  languages   Web-­‐based  communica-on   Challenges Over 20 different countries & cultures Data  Privacy  issues  
  • 24. Issues •  First saving period 2013: –  Easy to administer vs. legally bulletproof? –  Risk of reducing take up if too complex? •  Next saving periods 2014 onwards: –  Who to handle existing and new participants?
  • 25. Process •  We chose active data consent option: –  Consent from all employees allowing Outotec to transfer data to administrator •  Invitation to sign-up was sent only to those who gave consent –  2014 onwards consent ask again from everybody excluding participants •  Further acceptance on portal for data consent
  • 26. •  Over 1,500 participants in almost 20 countries around the world •  Take-up >33% China  18%     Australia  30  %     Brazil  12  %     Canada  22%   Chile  9%     Germany  25  %   Netherlands  55%   Finland  52%   Sweden  55    %   Norway  63%   South-­‐Africa  30  %   India  30  %   UK  80%   USA  23  %   Mexico  79  %   Global take-up 34% •  Over  1,500  par-cipants  in  nearly  20  countries   •  2014  take-­‐up  33%  and  2015  27%  -­‐  in  challenging  business  situa-on   Peru  25%     Zambia  33%   UAE     100%  
  • 27. Tips for global compliance ü  Country due diligence review ü  Undertake regulatory notifications and check they remain accurate and valid ü  Give employees information on processing activities ü  Obtain employees’ consent ü  Have a compliant contract with the administrator ü  Ensure all data transfers are compliant ü  Check data is accurate and deleted if no longer needed ü  Only process sensitive personal data for justified purposes
  • 28. Thank You Julian Cunningham-Day Linklaters julian.cunningham- day@linklaters.com Mike Pewton Solium GSP mike.pewton@solium.com Pekka Hukkanen Outotec pekka.hukkanen@outotec.com Nancy Price Linklaters nancy.price@linklaters.com